Guides
Webhooks
Signed HMAC notifications for every verification.
Configure a webhookUrl and webhookSecret on your relying party and Glemo
POSTs every verification result to your endpoint, signed with HMAC-SHA256.
Payload
The signature travels in the x-glemo-signature header (hex HMAC-SHA256 of the
raw body with your secret).
Verify the signature
Always compare with a timing-safe function, never ===.
Delivery
Webhooks are best-effort with basic retries — they never delay the verification response itself. Treat them as notifications, not as the source of truth: the API is.